Thanks, the first problem seems to be fixed now and I created an issue for
6+7.
That leave me with the problem 2: After logging into any status page I get
a 401 error, even though the log shows that authorization was successful (I
get "Executing authorization for expected admin roles [{}]", not followed
by "User [{}] is not authorized to access the requested resource allowed to
roles [{}]").
Also, I was looking at LdapAuthenticationProvider and wondered why you are
adding the attributes as authorities:
authorities.addAll(profile.getAttributes().entrySet().stream().map(e -> new
SimpleGrantedAuthority(e.getValue().toString())).collect(Collectors.toList()));
That just seems wrong. User attributes are not authorities, only roles are!
Op vrijdag 3 februari 2017 15:25:11 UTC+1 schreef Misagh Moayyed:
>
> Quick update: testing this a bit more I did find a few anomalies. I’ll put
> aside some time to review and apply fixes and if you want to track
> progress, do please open up that issue.
>
>
>
> Thanks.
>
>
>
> --Misagh
>
>
>
> *From:* Misagh Moayyed [mailto:[email protected] <javascript:>]
> *Sent:* Friday, February 3, 2017 2:34 PM
> *To:* [email protected] <javascript:>
> *Subject:* RE: [cas-user] Spring security problems
>
>
>
>
>
> 1. I configured security.basic.path=/cas/status/** and it triggers for
> Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for
> /cas/status/dashboard. Am I missing a config option somewhere?
>
>
>
> Possible. Difficult to say without seeing what the config looks like.
>
>
>
> 2. Are Spring Boot endpoints like /cas/status/health supposed to work?
>
>
>
> Yes. Open issues if you find the opposite is true.
>
>
>
> 3. Yes, but if you do that you bypass Spring Security and no longer have
> to option to validate roles (see https://github.com/apereo/cas/issues/2335
> ).
>
>
>
> Cool. Sounds like a PR to me.
>
>
>
> 5. It does need the .type, because LdapAuthenticationProvider uses it.
>
>
>
> See. See my previous comment.
>
>
>
> 6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with
> groups, but because it inherits
> from LdapUserAttributesToRolesAuthorizationGenerator it also checks the
> roleAttribute (in my code I temporarily moved de roleAttribute code from
> LdapUserAttributesToRolesAuthorizationGenerator.generate() to
> addProfileRoles()).
>
>
>
> If I am understanding you correctly, you’ll need to make sure only
> LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically
> treat your groupAttribute as CAS’ roleAttribute if possible.
>
>
>
>
>
--
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/e2c3c303-4a2b-42d1-b16b-556f6181c445%40apereo.org.